Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
SOC335---CVE-2024-49138-Exploitation-Detected — CVE-2024-49138 CLFS 권한 상승에 대한 SOC335 사고 대응 워크스루로, 경보 분류, 위협 인텔리전스 강화, 프로세스 트리 분석, 격리를 다룹니다. | Kitploit
도구/GitHubGitHub/fabianch20/soc335---cve-2024-49138-exploitation-detected
Indicator of Compromise (IOC) ManagementPrivilege EscalationVulnerability AnalysisMalware AnalysisDigital ForensicsThreat IntelligenceLearning & EducationIncident ResponseLog Analysis

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
Labs & Practice
GitHubfabianch20/soc335---cve-2024-49138-exploitation-detected

SOC335---CVE-2024-49138-Exploitation-Detected

CVE-2024-49138 CLFS 권한 상승에 대한 SOC335 사고 대응 워크스루로, 경보 분류, 위협 인텔리전스 강화, 프로세스 트리 분석, 격리를 다룹니다.

저장소 보기
16일 전아직 검토되지 않음

Rule CVE CVSS Status Verdict Host


> whoami

root@soc:~# cat case_file.txt

  Platform      : LetsDefend
  Case          : SOC335 - CVE-2024-49138 Exploitation Detected
  EventID       : 313
  Alert Time    : 2025-01-22T02:37:00+03:00
  Alert Type    : Privilege Escalation
  Difficulty    : Medium
  Role          : Security Analyst

  Hostname      : Victor
  IP Address    : 172.16.17.207
  Process User  : EC2AMAZ-ILGVOIN\LetsDefend
  Process Name  : svohost.exe   (masquerading svchost.exe)
  Process Path  : C:\temp\service_installer\svohost.exe
  Parent Proc   : C:\Windows\System32\WINDOWSPOWERSHELL\V1.0\powershell.exe
  File Hash     : b432dcf4a0f0b601b1d79848467137a5e25cab5a0b7b1224be9d3b6540122db9
  Device Action : Allowed

  MITRE ATT&CK  : T1059.001  PowerShell
                  T1055      Process Injection
                  T1068      Exploitation for Privilege Escalation
                  T1548      Abuse Elevation Control Mechanism
                  T1110      Brute Force

> ./playbook.sh --pivot-methodology

5단계 방법론으로, 각 단계는 다음 단계로 피벗하기 전에 WHO / WHAT / WHEN / WHY를 해결합니다.

┌─[ STEP 1: ALERT TRIAGE ]─────────────────────────────────────────────────────┐
│                                                                              │
│  WHO   : SIEM queue / SOC335 rule (EventID 313)                              │
│  WHAT  : svohost.exe spawned by powershell.exe outside System32              │
│  WHEN  : 2025-01-22 02:37:00 +03:00                                          │
│  WHY   : separates real EoP attempt from benign svc install                  │
│                                                                              │
│  $ filter process_name="svohost.exe" AND path!="*\System32\*"                │
│                                                                              │
│  PIVOT : hash + host isolated -> enrich with threat intel                    │
└──────────────────────────────────────────────────────────────────────────────┘

┌─[ STEP 2: THREAT INTEL ENRICHMENT ]──────────────────────────────────────────┐
│                                                                              │
│  WHO   : VirusTotal, CISA KEV, SentinelOne CVE DB                            │
│  WHAT  : hash flagged malicious; behavior maps to CVE-2024-49138 (CLFS EoP)  │
│  WHEN  : patched Dec-2024 Patch Tuesday; exploited pre-patch as 0-day, KEV-  │
│          listed                                                              │
│  WHY   : turns an unknown binary into a named, weaponized CVE with known TTPs│
│                                                                              │
│  $ vt hash b432dcf4a0f0b601b1d79848467137a5e25cab5a0b7b1224be9d3b6540122db9  │
│                                                                              │
│  PIVOT : malware + CVE confirmed -> validate on endpoint process tree        │
└──────────────────────────────────────────────────────────────────────────────┘

┌─[ STEP 3: ENDPOINT PROCESS TREE ]────────────────────────────────────────────┐
│                                                                              │
│  WHO   : Endpoint Security / EDR telemetry on host Victor                    │
│  WHAT  : child proc whoami.exe executes as NT AUTHORITY\SYSTEM               │
│  WHEN  : immediately after svohost.exe execution, same alert window          │
│  WHY   : proves exploitation SUCCEEDED, not merely attempted                 │
│                                                                              │
│  $ proctree --host Victor --pid 7640                                         │
│                                                                              │
│  PIVOT : escalation confirmed -> pivot to network logs for entry vector      │
└──────────────────────────────────────────────────────────────────────────────┘

┌─[ STEP 4: NETWORK & LOG PIVOT ]──────────────────────────────────────────────┐
│                                                                              │
│  WHO   : Log Management: RDP auth logs + firewall/netflow                    │
│  WHAT  : RDP brute force from 185.107.56.141; outbound traffic to C2         │
│  WHEN  : brute force precedes 02:37 alert; C2 traffic follows escalation     │
│  WHY   : completes the chain from initial access to impact; feeds IOC list   │
│                                                                              │
│  $ filter dst_ip=172.16.17.207 AND event_type=logon_failed,logon_success     │
│                                                                              │
│  PIVOT : full attack chain reconstructed -> containment & closure            │
└──────────────────────────────────────────────────────────────────────────────┘

┌─[ STEP 5: CONTAINMENT & CLOSURE ]────────────────────────────────────────────┐
│                                                                              │
│  WHO   : Incident responder / case owner                                     │
│  WHAT  : Device Action=Allowed -> malware NOT quarantined; host isolated     │
│  WHEN  : at alert time, within response SLA                                  │
│  WHY   : halts lateral movement/C2; documents evidence for TP closure        │
│                                                                              │
│  $ isolate-host Victor --reason "CVE-2024-49138 confirmed exploitation"      │
│                                                                              │
│  PIVOT : case closed as True Positive -> remediation (patch CLFS, harden RDP)│
└──────────────────────────────────────────────────────────────────────────────┘

> ./run_investigation.sh

[ Step 1 ] Alert Triage — SIEM / SOC335
$ cat alert_313.log

[i] EventID 313 | Rule: SOC335 - CVE-2024-49138 Exploitation Detected
[i] Parent -> powershell.exe (v1.0)
[i] Child  -> svohost.exe  "C:\temp\service_installer\svohost.exe"
[!] Legit svchost.exe NEVER runs outside C:\Windows\System32\
[+] ANSWER: filename masquerading detected (svohost vs svchost) -> escalate to full case

🔗 [LetsDefend SOC335 case data]

[ Step 2 ] Threat Intel Enrichment — VirusTotal + CVE research
$ vt hash b432dcf4a0f0b601b1d79848467137a5e25cab5a0b7b1224be9d3b6540122db9
도구 다운로드